Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
richr
New Contributor

P2P L2 VLAN from FGT to Dorm Connections

Currently, we have a FGT 800C and hope to get the 1000C shortly. Right now, most of our Dorm areas are on a L3 network at each building, however creating ACLs each time is a pain and everytime having to update them is a pain as well (even with a script). Would it be recommended to use the 800C - create vlans/subinterfaces off one of the 10G ports and then trunk the VLAN to the dorm connections?
3 REPLIES 3
Jeff_FTNT
Staff
Staff

Yes, is doable to create vlans/subinterfaces off one of the 10G ports and then trunk the VLAN to the dorm connections. The ACL(policy) is more clear . 1. Old L3 policy Incoming Interface->Outgoing Interface, need use different " Source Address" to identify host 2. New L2 policy, it arrange with VLAN VLANxx1 ->Outgoing Interface VLANxx2 ->Outgoing Interface ... VLANxxx ->Outgoing Interface 3. Another options: you may try set up VDOM on FGT, each Dorm areas belong to one VDOM, it is easy to manage .
ede_pfau
SuperUser
SuperUser

I don' t really see your problem - could you elaborate a bit on ' every time...' ? Jeff' s suggestions are perfectly viable but IMHO do not offer more efficiency. Either you work with address groups (moving new members into a group), or you create a new VLAN and policy (which is work as well, even scripted). You could use ' interface groups' a.k.a. Zones to keep the number of policies low, and add a new VLAN interface just to the Zone when you create a new one. I would refrain from using one VDOM per dorm - the amount of overhead is not worth the effort. For 5+ VDOMs you would better use a FortiManager to manage them. In a way, the FM is scripting for VDOMs. So, what do you have to do ' every time' ? Add a user, add a subnet or VLAN?

Ede


"Kernel panic: Aiee, killing interrupt handler!"
Ede"Kernel panic: Aiee, killing interrupt handler!"
richr
New Contributor

Thanks. Every time in the sense of if a student brings a university owned device into the dorm, they would radius auth but then also need to pass health checks. However, if we implement a third party device to help with this, then each L3 device needs the ACL updated for this. I would create a " Guest Network" zone and put all the vlans in there. I thought I would want to use more features of the Fortinet, and let that do all of the processing...
Labels
Top Kudoed Authors